Bug#462245: mantis: CVE-2008-0404 cross site scripting vulnerability on summary page

2008-01-23 Thread Patrick Schoenfeld
Tags 462245 unreproducible Hi, On Wed, Jan 23, 2008 at 02:15:24PM +0100, Thijs Kinkhorst wrote: > Could you check out the status of this in sarge? If it applies to sarge no, it does not affect sarge, nor does it affect sid. The thing is that this issue is affecting a part of mantis that has been

Bug#462245: mantis: CVE-2008-0404 cross site scripting vulnerability on summary page

2008-01-23 Thread Thijs Kinkhorst
Hi Nico, On Wed, January 23, 2008 14:52, Nico Golde wrote: > The code looks totally different. Some experience webapps > guy should check this. That's why I wrote it to Patrick :-) Thijs

Bug#462245: mantis: CVE-2008-0404 cross site scripting vulnerability on summary page

2008-01-23 Thread Nico Golde
Hi Thijs, * Thijs Kinkhorst <[EMAIL PROTECTED]> [2008-01-23 14:23]: > > CVE-2008-0404[0]: > > | Cross-site scripting (XSS) vulnerability in Mantis before 1.1.1 allows > > | remote attackers to inject arbitrary web script or HTML via the "Most > > | active bugs" summary. > > > > > > You can find a p

Bug#462245: mantis: CVE-2008-0404 cross site scripting vulnerability on summary page

2008-01-23 Thread Thijs Kinkhorst
Hi Patrick, > CVE-2008-0404[0]: > | Cross-site scripting (XSS) vulnerability in Mantis before 1.1.1 allows > | remote attackers to inject arbitrary web script or HTML via the "Most > | active bugs" summary. > > > You can find a patch for this on: > http://mantisbt.svn.sourceforge.net/viewvc/mantis

Bug#462245: mantis: CVE-2008-0404 cross site scripting vulnerability on summary page

2008-01-23 Thread Nico Golde
Source: mantis Severity: important Tags: security patch Hi, the following CVE (Common Vulnerabilities & Exposures) id was published for mantis. CVE-2008-0404[0]: | Cross-site scripting (XSS) vulnerability in Mantis before 1.1.1 allows | remote attackers to inject arbitrary web script or HTML via